CVE-2016-8858 is a vulnerability in OpenBSD OpenSSH
Published on December 9, 2016
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."
Products Associated with CVE-2016-8858
Want to know whenever a new CVE is published for OpenBSD OpenSSH? stack.watch will email you.
Exploit Probability
EPSS
27.13%
Percentile
96.29%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.